SB2022111725 - Information disclosure in Zulip Server
Published: November 17, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information exposure through timing discrepancy (CVE-ID: CVE-2022-41914)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a weak generation mechanism of SCIM bearer tokens. A remote attacker can infer the value of the SCIM bearer token by performing a sophisticated timing analysis on a large number of failing requests. If successful, this would allow the attacker to impersonate the SCIM client for its abilities to read and update user accounts in the Zulip organization.
Remediation
Install update from vendor's website.